Skip to content

Security

ArchNGN is built with strong security practices to keep your enterprise architecture and business data safe and secure at every layer. This includes relying on state-of-the-art infrastructure, secure encryption, and independently verified security controls provided by our infrastructure partners.

Under our shared responsibility model, ArchNGN secures the application layer and the underlying cloud infrastructure it runs on (Amazon Web Services, Microsoft Azure, and Google Cloud, depending on your hosting environment). This includes protecting the backend services, databases, and deployment environments against threats through security controls, monitoring, and automated private networking configurations.

Customers are responsible for how they use ArchNGN. This includes configuring workspace access safely, maintaining the security of your sign-in credentials, determining what metamodel and object data is uploaded to our platform, and managing secure credentials for integrations. Connector credentials you supply are held in an encrypted secrets store and scoped to read-only access you control.

Pipelines, AI coding agents and security tooling authenticate with API tokens, minted under Settings → Security. Tokens are bound to your account, carry a fixed set of scopes, and can be bound to specific workspaces. Only a hash is stored; the plaintext is shown once at creation and cannot be recovered.

Scopes are separated so a credential can be sized to its job — reading the architecture, running design checks, waiving a finding and reading the audit trail are four different permissions. Revocation is immediate, rotation is mint-then-revoke so there is no window of downtime, and every action a token takes is attributed to it in the audit log.

A resource belonging to another account answers not found rather than forbidden, so no endpoint can be used to discover whether another tenant’s identifier exists.

See REST API for the full scope list and token handling guidance.

ArchNGN is currently undergoing certification for the following:

  • SOC2 Type II
  • ISO 27001
  • GDPR
  • HIPAA

For specific questions about compliance or organizational capabilities, please reach out to us directly at security@archngn.com.

ArchNGN account regions are considered global with the exception of Enterprise accounts. Speak to your account manager during setup to configure the region that suits your needs. The enterprise regions available are:

  • United States
  • European Union
  • Asia & Oceania

Region-based components include all core infrastructure: primary databases, object storage, background task queues, compute instances, and AI services.

Managed identity services used for authentication (such as Amazon Cognito, Microsoft Entra External ID, or Firebase Authentication, depending on your hosting environment) remain subject to their provider’s standard multi-region and routing implementations.

If you suspect a security issue or vulnerability within ArchNGN, we ask that you report it to us immediately so we can fix it.

Please send all security-related reports and inquiries to: security@archngn.com.